Linux system files tamper-script

 
Linux system files tamper tamper-proof script script files, a file has been modified, immediately sending alarm messages
  1. #!/bin/bash
  2. #description: check files shell
  3. #author:coralzd powered by www.freebsdsystem.org
  4. checkdir=/data/www/bbs.xxx.com
  5. ipadd=ifconfig |grep "inet" |cut -c 0-36|sed -e 's/[a-zA-Z: ]//g' |grep -v "127.0.0.1"
  6. while [ 1 ]
  7. do
  8. DATE=date +%Y-%m-%d.%H:%M:%S
  9. find ${checkdir} ( -path ${checkdir}/forumdata/threadcaches -o -path ${checkdir}/forumdata_1/threadcaches -o -path ${checkdir}/forumdata_1/templates -o -path ${checkdir}/f
  10. orumdata_1/cache -o -path ${checkdir}/forumdata/dzwxuser -o -path ${checkdir}/attachments -o -path ${checkdir}/forumdata/cache -o -path ${checkdir}/forumdata/templates -o -path
  11. ${checkdir}/forumdata/dzwxuser -o -path ${checkdir}/dzwxuserid/cache -o -path ${checkdir}/forumdata_1 ) -prune -o -name "*php" -mmin -1 -print >/tmp/tmpdd
  12. SZ=ls -la /tmp/tmpdd|awk '{print $5}'
  13. if [ "${SZ}" -gt "2" ]; then
  14. SN=cat /tmp/tmpdd
  15. echo ${DATE} ${SN} >>/var/tmp/checkfile.log
  16. wget http://10.10.10.10/phpsms/smsu.php?phone=15012345678&msg=%E7%95%99%E6%84%8F%EF%BC%9A${ipadd}_%E5%8F%AF%E8%83%BD%E5%87%BA%E7%8E%B0%E6%96%87%E4%BB%B6%E7%AF%A
  17. 1%E6%94%B9 -O /dev/null >/dev/null 2>&1
  18. fi
  19. sleep 60
  20. done

Leave a Reply

Your email address will not be published. Required fields are marked *